The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
AI for managing contracts, regulation, governance, and organisational risk. Contract review and e-discovery are good practice with proven ROI; regulatory monitoring and due diligence are advancing steadily. Most of the domain sits at leading-edge — adoption is constrained by liability concerns and the need for domain-expert validation rather than by tooling gaps.
The deadline everyone had been planning around has passed. On 2 August 2026 the EU AI Act's transparency and risk-management obligations took effect, and with them a regime that demands not disclosure but demonstration: unredacted access to risk-management frameworks within five business days, an exhaustive "design history file" covering architecture, data provenance, evaluation results and monitoring with ten-year retention, and penalties reaching €35M or 7% of global turnover. Article 87 simultaneously extended whistleblower protection to AI governance violations, and the Commission opened a dedicated reporting channel for them. The high-risk Annex III obligations are deferred to December 2027, which buys time on scope but not on posture. What arrived this fortnight was not a new capability. It was the moment the domain's central question changed from whether AI works to whether you can prove, on demand and in writing, that it worked properly.
On that question the sector is not ready, and the evidence is now unusually consistent across independent sources. Schellman surveyed 525 enterprise professionals and found 74% believe they could pass an AI compliance audit today while only 27% describe their governance as genuinely mature. Kyndryl's 1,100-leader study found only 27% maintain a registry and monitoring capability covering all their AI systems. Qapitol's field research across 50 banks put comprehensive governance frameworks at 31%, with 87% below optimised maturity and median EU AI Act readiness at 38%. Kiteworks found half of surveyed organisations cannot produce a complete AI data-access audit trail within one business day; a 720-respondent Singapore survey found 94% of firms using or testing autonomous agents against just 29% able to produce an audit trail of an AI decision. The Financial Stability Board sharpened the diagnosis: 84% of financial institutions have named an AI owner, but 46% of those only partially understand what their own systems are permitted to do. Accountability has been assigned; decision boundaries have not been documented. That is precisely the gap an examiner opens with.
The more interesting development is economic. For three years governance has been priced as a tax on deployment. This fortnight's evidence recasts it as the variable that determines whether deployment happens at all. Domino Data Lab's survey of 639 senior AI leaders found organisations with fully integrated governance were 3.9 times more likely to have agentic systems running in governed production — 67.5% against 17.2% — and that 75% of them reported improved delivery velocity, against 23% where governance lagged. A Forrester study of 409 director-level buyers found 55% high confidence among those describing themselves as operating "agentic control" versus 22% in "agentic chaos". TrustArc's privacy benchmarking found integrated programmes scoring 85% on its Global Privacy Index against 18% for fragmented ones — a 67-point spread driven by integration discipline rather than platform choice. Box's 1,640-leader study captured the tension precisely: 76% say governance slows deployment today, yet 93% believe better governance will let them scale faster over time. These are correlations from self-reported surveys, not controlled trials, and the causal arrow may partly run backwards — organisations capable of building governance are capable of building other things too. But the consistency across five independent instruments is hard to dismiss, and it reframes the buying decision. The constraint on scaling AI in this domain is no longer model quality. It is whether the evidence layer exists.
Regulatory change monitoring and impact assessment crossed into settled practice this fortnight — the domain's only maturity movement, and a meaningful one. The trigger was not a capability leap but the convergence of commercial proof and supervisory expectation. Haast, an agentic compliance automation platform, raised a $12M Series A from Peak XV and DST Global on 4.5x revenue growth with zero churn and Fortune 500 customers, targeting the 70% of compliance-team time still consumed by manual regulatory review. Gartner's 2026 Market Guide for Regulatory Intelligence Solutions quantified the remaining runway: 46% of organisations use no regulatory intelligence technology at all and 20% still run manual trackers. StarCompliance's survey of 300-plus compliance professionals at global financial institutions found 76% increased their compliance budgets year on year and 67% deploying or piloting AI. Most consequentially, supervisors changed what they audit. Examiner analysis of USAA's $140M FinCEN penalty, alongside enforcement actions against Bank of America, City National and TD, shows regulators now demanding proof that an alert became a working control — not merely that the alert was received and logged. US Customs and Border Protection's ruling HQ H350722 went further, establishing the first formal American regulatory guidance mandating human-in-the-loop oversight for AI-assisted trade compliance determinations. Monitoring has become an assumed capability; the scrutiny has moved downstream to what you did with the output.
Everything else held position, but the texture changed in three directions. Regulators started specifying that AI must supervise AI: the FSB's Sound Practice 10 framework establishes meta-monitoring as a requirement for banking governance, defining six mandatory oversight capabilities on the explicit premise that continuous human oversight at agentic scale is impractical — and Anthropic shipped a Compliance API providing continuous monitoring and cryptographic audit trails of agent behaviour in place of periodic sampling. Independent research cut hard against the adoption momentum: separate studies documented "Safety Drift" (agents eroding compliance intent across extended interactions) and "Operational Hallucination" (persistent tool loops from decoupled execution state), while agents were shown to systematically fail written compliance policies and lose policy adherence as context grows. One analyst report noted AI agent rollbacks now outpacing deployments on error rates and opaque decision-making. And the sanctions wave kept escalating: trackers now catalogue roughly 1,490 to 1,598 court decisions involving AI-fabricated material, with incident rates climbing from around 200 in mid-2025 to five or six daily by spring 2026. An Illinois appellate court imposed a higher-than-typical fine explicitly to deter hallucinations, and a UK Upper Tribunal found the Home Office had used a hallucinated policy document to refuse an asylum claim, which the judge characterised as analogous to bogus evidence. A federal lawsuit in the US Court of Federal Claims now alleges AI errors tainted a $450M Army contract evaluation by assigning false weaknesses and inflating a competitor's strengths — the first documented case where hallucination is alleged to have moved a nine-figure procurement.
Governance has flipped from cost centre to production prerequisite. Five independent surveys this fortnight found the same pattern: organisations with mature governance are several times more likely to have AI actually running in production, not less. Domino's 639-leader study puts the multiple at 3.9x (67.5% versus 17.2%); TrustArc's privacy benchmark shows a 67-point performance gap between integrated and fragmented programmes. The old framing — that controls slow you down — survives in the moment (76% of IT leaders say governance slows deployment today) but not over the cycle (93% expect it to accelerate scaling).
The audit trail, not the model, is the binding constraint. Half of organisations surveyed cannot assemble a complete AI data-access trail within a business day; only 29% of surveyed Singapore firms can produce an audit trail of an AI decision, against 94% using or testing agents; 52% of one vendor's customers cannot verify what their AI systems actually did and 48% cannot trace activity end to end. Against DORA, NIS2 and the EU AI Act — all of which now demand artefact-level evidence rather than narrative policy — this is the exposure that matters, and it is an infrastructure problem no model upgrade resolves.
Averages sell the tools; the tails create the liability. Independent MIT CSAIL and Harvard benchmarking put contract review error rates at 6–13% on standard commercial agreements, rising to 15–22% on specialised instruments including cross-border and restructuring work. Legal research hallucination runs 8–17%, reaching 23% on state administrative and tribal court matters. Peer-reviewed work on customs classification found AI agents at 49.4% accuracy on ten-digit HS codes against 95% for domain experts — a 45-point gap that persisted through test-time scaling. A newly documented "choice of law" blind spot compounds it: tools trained predominantly on US agreements apply common-law reasoning to civil-law jurisdictions, systematically misreading force majeure, material adverse change and good-faith obligations in cross-border deals.
Verification is failing structurally, not accidentally. Analysis of the Sullivan & Cromwell filing found its two-layer safeguard — firm policy plus secondary attorney review — failed simultaneously under deadline pressure, meaning advisory verification collapses exactly when it is most needed. The Withers matter exposed a second-order failure: adversarial checking breaks down when both sides of a negotiation run the same generation stack. Meanwhile 300-plus judge-level standing orders now govern AI disclosure with no unified national rule, and Ironclad's 2026 survey found 92% of legal teams using AI while 51% have no formal AI error policy. The profession has adopted the tools and not the mechanical citation-checking infrastructure they require.
Vendor scale is real; implementation failure is equally real. Thomson Reuters reported CoCounsel monthly users quadrupling year on year, Westlaw deep-research searches up sevenfold in six months, and generative AI now 30% of annual contract value against 15% five quarters earlier, with one million users across 107 countries; Regnology's reporting platform is deployed at 19 of the world's 20 largest banks; Descartes posted record quarterly revenue of $193.6M at a 46% EBITDA margin while extending AI agents into sanctioned-party screening. Yet 78% of organisations have invested in contract lifecycle management over five years and more than half report the implementations do not meet their needs, with 92% exceeding planned timelines; missed renewals cost an average $393k a year and 71% of firms cannot reliably locate 10% of their active contracts. In privacy, market-leader friction surfaced explicitly — eight-month implementations, 20-to-40-person teams, renewal price increases reported at 10 to 30 times — and a lawsuit against the NFL documented a consent platform deployed correctly on the surface while 186 third-party trackers kept firing after opt-out. Buying the platform and achieving the control remain separate projects.
Home Office used 'AI hallucinated' information to refuse asylum claim, judge suggests (news-coverage) — A UK Upper Tribunal judge called the fabricated policy document "analogous to bogus evidence," the starkest single case behind the fortnight's sanctions wave and a reminder that hallucination consequences now reach high-stakes government decisions, not just court filings. https://www.theguardian.com/uk-news/2026/jul/28/home-office-used-ai-hallucinated-information-to-refuse-asylum-claim-judge-suggests
Survey finds agentic AI audit gap in Singapore firms (adoption-metric) — The 720-respondent APAC survey behind the summary's headline statistic: 94% of firms use or test agentic AI, but only 29% of that same population can produce an audit trail of a single AI decision. https://sbr.com.sg/information-technology/news/survey-finds-agentic-ai-audit-gap-in-singapore-firms
74% of Enterprises Say They Are Audit-Ready for AI, Only 27% Actually Are (adoption-metric) — Schellman's 525-respondent benchmark is the anchor data point for the "sector is not ready" argument, and the confidence-versus-maturity gap it exposes recurs across every governance survey cited this fortnight. https://www.cpapracticeadvisor.com/2026/07/29/74-of-enterprises-say-they-are-audit-ready-for-ai-only-27-actually-are/187545/
New Research Finds That Despite Improved Productivity, AI ROI Fails to Outpace Spend (adoption-metric) — Domino Data Lab's 639-leader survey supplies the pivot statistic of the summary: organisations with fully integrated governance are 3.9x more likely to have agentic systems running in governed production, recasting governance as a production prerequisite rather than a deployment tax. https://www.carriermanagement.com/news/2026/07/22/290293.htm
Financial Stability Board points banks towards AI monitoring AI as human oversight reaches its limits (industry-report) — The FSB's Sound Practice 10 framework operationalises the claim that continuous human oversight of agentic systems is no longer treated as sufficient by regulators — AI must now supervise AI at scale. https://www.theasianbanker.com/updates-and-articles/financial-stability-board-points-banks-towards-ai-monitoring-ai-as-human-oversight-reaches-its-limits
Can regulation become machine-readable? & US RegTech investments stumble in Q2 (industry-report) — Haast's $12M Series A on 4.5x revenue growth and zero churn is the commercial proof point behind the claim that regulatory-change monitoring "crossed into settled practice this fortnight," the domain's only maturity movement. https://www.linkedin.com/pulse/can-regulation-become-machine-readable-us-regtech-investments-nbwle
Regulatory Change Implementation Record: Prove the Alert Became a Working Control (opinion) — Examiner analysis of USAA's $140M FinCEN penalty is the evidence behind the fortnight's most consequential regulatory shift: supervisors now audit whether an alert became a working control, not merely whether it was received and logged. https://risktemplate.com/blog/2026-07-27-regulatory-change-implementation-record-evidence-working-control/
AI Errors Tainted Army's $450 Million Contract Award, Suit Says (news-coverage) — The first documented case where alleged AI hallucination is claimed to have moved a nine-figure procurement decision — exactly the "tail" outcome the summary warns that averaged benchmark error rates obscure. https://news.bloomberglaw.com/federal-contracting/ai-hallucinations-tainted-armys-missile-test-award-suit-says
The Verification Layer Legal AI Still Doesn't Have (opinion) — Analysis of the Sullivan & Cromwell filing shows its two-layer safeguard — firm policy plus secondary attorney review — failing simultaneously under deadline pressure, direct support for the tension that verification is failing structurally rather than accidentally. https://www.linkedin.com/pulse/verification-layer-legal-ai-still-doesnt-have-michael-villarmia-ugt1c
NFL Privacy Lawsuit Alleges Tracking Continued After Users Opted Out (news-coverage) — A consent-management platform deployed correctly on the surface while 186 third-party trackers kept firing after opt-out — the concrete case behind the summary's closing line that buying the platform and achieving the control remain separate projects. https://captaincompliance.com/education/nfl-privacy-lawsuit-alleges-tracking-continued-after-users-opted-out/